
Certified Secure Software Lifecycle Professional
Domain 4Objective 1
Define the Security Architecture CSSLP Practice Questions (Page 13)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 117 practice questions to prepare you well beyond it. (estimate)
117questions here
24free pages
43concepts
15%of the exam
Questions 61–65
- 61
A fitness tracking app collects the user's location data to map their running routes. The app also shares this data with third-party advertisers. The privacy officer is concerned about the implicit data collection and the potential for misuse of location data. Which of the following is the most appropriate mitigation?
Select an answer first - 62
What is a common client-side threat that tricks a user's browser into making an unwanted request?
Select an answer first - 63
Which security threat is particularly relevant to client-server architecture?
Select an answer first - 64
A company is migrating its legacy two-tier application to a three-tier architecture (web, application, database). The security architect is defining the security controls for each tier. The web tier is internet-facing and handles user input. The application tier contains business logic. The database tier stores sensitive data. Which of the following is the most important control to implement at the web tier?
Select an answer first - 65
In a mesh network security architecture, which characteristic is most essential for maintaining secure communication between nodes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.